Stem legal
Stem Business OS Privacy and Platform Data Policy
Stem Business OS is the product platform that includes Stem POS and Stem Invoicing. This policy explains what we handle when you visit our website, create an account, operate a till, issue an invoice, ask for support or use a connected service.
- Effective
- 4 September 2026
- Version
- 2026-09-04
1. Who is responsible
Stem Business OS is operated by Stem Technologies Uganda. Stem is the controller for website visits, enquiries, account administration, security, billing, support and product-operation information that we decide how to use.
Your business is normally the controller for personal data about customers, staff, suppliers and other people entered into your workspace. Stem processes that information for your business under the Data Processing Addendum. Direct privacy requests about a merchant’s records should normally go to that merchant first.
2. Information we handle
- Account and contact details, including name, business, email, phone, role and sign-in status.
- Store and operational records such as products, prices, stock, sales, returns, customers, suppliers, credit, staff activity, invoices and payment method/reference.
- Device, application, sync, security and diagnostic details such as app version, device identity, IP address, authentication events and audit records.
- Billing, order and support information, including plan, payment status, hardware delivery details, enquiries and correspondence.
- Website and network information such as page path, referrer, browser and device type, operating system, approximate country or city, performance timings, IP address and security signals. Section 4 explains which analytics and anti-abuse providers receive this information and which controls apply.
Stem does not need payment-card security codes or passwords for other services. Do not put them into free-text fields or support messages.
3. Google user data and connected Google Drive
The app name shown by Google is Stem Business OS. It is the shared account and integration platform for Stem POS, Stem Invoicing and the Stem back office. These products offer Google Sign-In for account access. A workspace administrator may separately choose to connect Google Drive for document exports. The features are optional and separate: signing in with Google does not by itself give Stem access to Google Drive.
Google data we access. Google Sign-In supplies a stable Google account identifier, verified email address, display name and, when available, profile image. If an administrator explicitly connects Google Drive, Stem requests the drive.file permission. That permission lets Stem create and access only the Drive files and folders created or opened through Stem. We create a folder named “Stem Invoicing” and upload only the invoice or other business-document PDF that an authorised workspace user chooses to export. Google may also return the app-created file or folder ID, file name, view link, granted scopes and token status. Stem does not request access to, search, download or read unrelated files already in the user’s Drive.
How we use Google data. We use identity data only to authenticate the user, link or create the corresponding Stem account, show the account name or profile image, secure the session and support the requested workspace. We use Drive authorisation only to create the Stem Invoicing folder, upload a user-selected document, return a link to the new file, maintain the connection and diagnose a failed export. We do not use Google user data for advertising, retargeting, credit decisions or any unrelated purpose.
Storage and protection. Stem stores the Google account link and basic profile fields with the Stem account. For a Drive connection, the server stores the granted scopes, connection time, connected Stem account, app-created folder ID and an encrypted Google refresh token so that authorised exports can continue without asking the administrator to sign in every time. Google access and refresh tokens are kept server-side, encrypted at rest where persisted, protected in transit and are not placed in PowerSync, exposed to other tenants or shipped inside the client application.
Sharing and human access. Google user data is exchanged with Google to complete authentication and the requested Drive operation, and may be processed by vetted infrastructure providers only as needed to host, secure and support Stem. We do not sell Google user data, share it with advertising platforms, data brokers or information resellers, use it to determine creditworthiness, or use it to train general-purpose or non-personalised artificial-intelligence or machine-learning models. Stem personnel do not read Google Drive content except when the user gives affirmative permission for a specific support case, when necessary to investigate abuse or a security incident, or when required by law.
Retention, revocation and deletion. The Google identity link is normally retained while the Stem account remains active. Drive credentials are retained only while the workspace keeps Drive connected. Disconnecting Google Drive in Stem asks Google to revoke the token and clears the locally stored Drive credential, scopes, connection details and folder reference. Revoking Stem in the user’s Google Account also stops future access. Files already exported remain in the user’s own Google Drive until the user deletes them; disconnecting Stem does not silently delete those files. A verified account-deletion request removes or de-identifies the associated Google account data subject to the legal and backup limits in this policy. Start at Delete an account.
Stem’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. Stem’s own analytics, Google Analytics, Cloudflare analytics and Turnstile
Stem’s own sign-up analytics. On public marketing pages and the sign-up and onboarding screens, Stem’s own servers record page path, referring website, campaign tags in the link (utm parameters), device type, operating system, browser, screen size and language, together with the sign-up step reached (for example “form submitted” or “account created”). This tells us how many visitors become customers and on what devices. It sets no cookie and stores no persistent identifier: a random session id is kept only in the browser’s session storage and disappears when the tab closes, and the connection address is combined with a random daily salt into a one-way hash that cannot be reversed or linked across days, so a visitor cannot be recognised tomorrow. Once an account is created the record is linked to that business account so we can see which visits led to sign-ups. This data is not shared with any third party, is not mounted inside the authenticated till, invoicing or back-office interface, and is deleted after 400 days.
Google Analytics on public pages. Stem uses Google Analytics 4 on public marketing and legal pages to understand visits, page use and whether those pages are useful. It is not mounted in the authenticated tenant, till, invoicing or back-office interface, and Stem does not send customer records, invoice contents, product records or signed-in user identifiers to Google Analytics. The Google tag loads when a public page opens. Before a visitor chooses, Google Consent Mode sets analytics storage, advertising storage, advertising user data and advertising personalisation to denied. In that state, a cookieless measurement request still reaches Google, but no Analytics cookie or persistent Analytics client ID is stored. If the visitor accepts analytics, Google Analytics may store the first-party _ga identifier and receive page paths, referrers, session and interaction events, browser and device information and approximate location derived from the connection. We do not enable advertising storage, advertising user data or advertising personalisation through this consent control.
The choice is stored in the visitor’s browser and can be changed at any time through “Analytics settings” in the website footer. Stem does not keep a separate copy of raw Google Analytics events. In the current Google Analytics property, event-level data associated with cookies or identifiers is configured for 2 months and user-level data for 14 months; the user-data period resets on new activity. Google explains that standard aggregated reports are not governed by those user and event retention controls. See Google Analytics data safeguards.
Cloudflare Web Analytics and delivery security. The website is delivered through Cloudflare, which may automatically add its Web Analytics performance beacon to web pages on this domain. Cloudflare receives ordinary connection information such as IP address and user-agent details to deliver and protect the site. Its Web Analytics beacon reports page-performance timings and aggregate traffic dimensions such as country, host, path, referring host, device type, browser and operating system. It does not receive form values through the beacon, does not log query strings for Web Analytics and does not track an individual across Cloudflare customers. Unsampled beacon data is retained by Cloudflare for 7 days, after which Cloudflare aggregates it for longer-term reporting; Stem can access Web Analytics reports for up to six months. See Cloudflare’s Web Analytics documentation.
Cloudflare Turnstile on web sign-in and registration. Stem uses Turnstile to distinguish legitimate browser requests from automated abuse on web sign-in and sign-up forms. The widget may process the client IP address, TLS fingerprint, user-agent header, site key and associated website origin, plus browser and environment signals needed to produce a short-lived challenge token. Stem sends that token and, when available, the client IP address to Cloudflare’s Siteverify service for a pass/fail decision. The token is single-use and is not used by Stem for advertising. Turnstile is not used in the native till login. Stem does not send the entered password, PIN or other form values to Cloudflare through Turnstile. Cloudflare describes its processing in the Turnstile Privacy Addendum.
5. Why we use other information
- To create and secure accounts, enrol devices, sync records and provide requested features.
- To perform the contract, confirm billing, deliver support and communicate service information.
- To prevent abuse, investigate incidents, keep audit evidence and comply with legal duties.
- To improve reliability and usability using necessary diagnostics and optional, consent-based website analytics.
- To establish, exercise or defend legal claims and respond to lawful authority requests.
Depending on the context, the legal ground is performance of a contract, compliance with law, a legitimate interest that does not override a person’s rights, consent, or another ground available under applicable law. We do not sell personal data.
6. Who receives other information
Authorised users in your business receive information according to their role. Providers acting for Stem may process only what is needed to supply their service. These include hosting and database providers, PowerSync for authorised offline synchronisation, Cloudflare for website delivery, security, Turnstile and Web Analytics, Google for optional identity, Drive and public-page analytics, and providers used for storage, email or message delivery, support, document rendering and payment confirmation. Their access is limited by contract, configuration and access controls appropriate to the service.
Information may also be disclosed during a legitimate business transfer with appropriate safeguards or when an authorised user directs Stem to connect or submit to another service. We do not sell personal data, give one merchant’s data to another merchant, or let service providers use workspace data for their own advertising.
7. URA, EFRIS, government and legal disclosures
Merchant-directed tax reporting. Where a merchant enables a Uganda Revenue Authority integration, is legally required to use EFRIS, or asks Stem to fiscalise a document, Stem may transmit to URA/EFRIS the taxpayer, buyer, product or service, quantity, price, discount, tax, payment, invoice or receipt, cancellation/credit-note and related transaction details required by the applicable EFRIS interface. URA may return fiscal document identifiers, verification codes, status, errors and other tax records. This transfer is made to issue or manage the merchant’s fiscal document, comply with tax law and keep the resulting audit record; it is not an advertising disclosure. A merchant should not enable or use a government submission for data it is not authorised to report.
Other lawful requests. Stem may disclose the minimum information reasonably necessary to URA, the Personal Data Protection Office, courts, law-enforcement bodies or another competent public authority when the merchant directs a lawful submission, when a binding law, court order or valid official demand requires it, or when disclosure is necessary to investigate fraud, abuse, a security incident or a serious threat to a person. Where legally permitted and reasonably practical, Stem verifies the request, limits the response, challenges an overbroad demand and notifies the affected customer.
Stem does not provide governments with voluntary, continuous or unrestricted access to the service and does not sell data to public authorities. Google identity or Drive data is not shared with a government unless disclosure is legally required. A business document created in Stem may be submitted to URA/EFRIS and separately exported to Google Drive, but enabling both features does not give URA access to the user’s Drive. Files kept in a user’s Google Drive remain under that user’s Google account and may separately be subject to Google’s own lawful-disclosure obligations.
8. International processing
Some infrastructure or service providers may process information outside Uganda. Before doing so, Stem assesses the provider and uses the contract, consent or other safeguard required by applicable law. Contact us for the current provider and processing-location information relevant to your account.
9. Retention of other information
We keep information only for as long as needed for the purposes above. Account and workspace data is normally kept while the account is active and through the verified deletion process. Authentication-attempt records are scheduled for up to 90 days, tenant audit records up to 365 days and platform security/audit records up to 730 days, unless an incident or legal duty requires longer.
Invoices, tax, transaction, payment, contract and dispute records may be retained for the period required by applicable law. Backups age out through their protected rotation and are not restored for routine use. De-identified information that can no longer reasonably identify a person may be retained for service analysis.
10. Security
Stem uses role-based access, authentication controls, encrypted network transport, tenant separation, audit logging, rate limiting, protected credentials and operational backup controls. No internet or device system is risk-free; tell us promptly if you suspect unauthorised use.
11. Your choices and rights
Depending on the law that applies, you may ask to access, correct, export, restrict, object to, or delete personal data, withdraw consent, or complain to a data-protection authority. Withdrawing consent does not undo earlier lawful processing. You can change optional website analytics at any time from the marketing-site footer.
We verify requests before acting and may need to preserve records that law requires. Start an account request at Delete an account, or contact us for another privacy request. We do not discriminate against a person for exercising a privacy right.
12. Children
Stem is a business service for adults and is not directed to children. Do not create a Stem account for a child or deliberately place children’s personal data in the service unless a lawful business need and every required safeguard have been agreed with Stem in writing.
13. Changes and complaints
We publish a new effective date when this policy changes and give reasonable notice of a material change. A privacy notice is acknowledged as information; it is not treated as blanket consent for unrelated processing.
Contact Stem first so we can investigate. You may also complain to Uganda’s Personal Data Protection Office or another competent authority where you live.
Operator and contact
Stem Business OS, including Stem POS and Stem Invoicing, is operated by Stem Technologies Uganda. Our address for service is Kampala, Uganda.
Call +256 706 370617, message us on WhatsApp, or use our contact form.